Open protocol · MIT verifier · Public ledger

An open protocol for provable AI source data

Works on any structured data — starting with the books.

Proof of exactly what data an AI used, who approved it, and that it hasn't changed since. The data stays yours; only a fingerprint goes on a public ledger.

Free to verify · no account · no dependency on us
The problem

The number changed.
Nobody was told.

January 2025
£100,000
Same line, July 2025
£200,000
Standard feature. Authorised user. No external record.

Any authorised user of any accounting system can reopen a closed period, change a historical figure and close it again. Not an attacker — an ordinary person using a supported feature. Both numbers came from the real system. Neither is flagged as having changed.

Now connect an AI copilot. It reads whichever version exists at the moment you ask, and nothing outside the vendor's own database records which one that was.

And when it surfaces
AU$440k
refunded on an AI-assisted government report
73%
of references in one report hallucinated
40 of 45
citations fabricated in another
Three of the largest professional-services firms, 2025–26. Reported by mainstream outlets; sources on request.
Why now

The deadline is fixed.

2 Dec 2027

Annex III high-risk AI: automatic, traceable, tamper-evident record-keeping becomes an obligation under the EU AI Act. Annex I embedded systems follow on 2 Aug 2028.

Live now

General-purpose AI penalties and Article 50 transparency duties have been enforceable since 2 August 2026 — up to €15M or 3% of global turnover.

Regulation (EU) 2024/1689. Annex III timing per the 2026 Digital Omnibus deferral. The Act requires traceability; it does not mandate any particular technology.

How it works

Retrieve, don't generate.

1

Strip the personal data

From a ledger, or any structured dataset. Pseudonymised or fully anonymised, depending on how you deploy it.

2

A human approves

A named reviewer signs off the dataset. Configured once at dataset level, not per query.

3

Anchor the proof

A fingerprint and timestamp go onto a public ledger. The data itself never does.

4

AI reads the approved store

Approved records only — or the answer declines. Not the raw ledger.

Every answer traces back to a record, a named approver and an on-chain timestamp — and anyone can check that trace without an account and without trusting us.

Why this isn't a commodity

Anchoring is easy.
Independent checking is the hard part.

Anchors a hash externally Publishes how to reproduce the check
Self-hosted digital signatures
"Blockchain-secured" vendors
OpenBookChain

An anchored hash answers "was this hash tampered with?" It does not answer "can I, from outside, confirm this hash matches the real record?" That second question is the only one that matters — and answering it in public is the whole company.

We hold nothing of yours. Your own wallet, your own keys, your own storage — and in client-hosted mode we never see raw personal data at all.

Hash anchoring is mature and widely available. The published, reproducible verification method is the differentiator — not the anchor.

Straight answers

Not a truth machine.
A chain of custody.

What data

the AI used

Who

approved it

When

they approved it

Unchanged

since that moment

We do not claim the data is true. No system can certify truth at the point of entry, and anyone who says otherwise is selling an illusion. What we make permanent is accountability: a bad figure isn't sanctified by the ledger — it's pinned to a name and a timestamp, visible, challengeable and correctable.

One limit, before you find it. A single anchored record proves that record hasn't changed. It doesn't prove nothing was left out of a set. Batch anchoring over a Merkle tree answers that — hash the period, publish the root — and it's a funded item on our roadmap, not a solved one.

The product

Built before we raised anything.

Live today
  • The full pipeline, end to end
  • PII-strip → human approval → anchor
  • A live connection to a real accounting system
  • Two published open standards, obc-v1 and obc-v2
  • The verification method, published openly
  • Per-tenant wallets; client-hosted deployment option
Next

Two founders. Nothing raised. We never claim a connector that isn't shipped, and we publish what isn't built yet on the same page as what is.

Who it's for

When someone outside your business has to take your figures on trust.

We're most useful where a contract already gives someone the right to check your numbers — and no practical way to do it.

Franchisors & licensors

Royalty and revenue-share figures self-reported by hundreds of separate businesses, audited once a year at most.

Grant-makers & funders

Claims certified after the fact by an independent auditor, against records that must still be there and unchanged.

Auditors & advisers

Evidence whose reliability you have to stand behind — and which a client's system can silently revise.

Anyone deploying AI on finance data

Where you'll later be asked what the system was told, by whom, and whether it's still the same.

Pricing

Free to verify. Paid per provable source.

One subscription per connected source, per year. What the source is used for sets the band. Checking a proof is free, for anyone, forever — we don't charge the person doing the checking.

Adoption

Nobody outside is asking yet

Low-cost entry, so the trail starts accumulating before it's needed.

Professional

Your clients are asking

Adviser-managed entities, bundled across a client book.

Regulated

A regulator, funder, auditor or acquirer is asking

Highest exposure and value at risk. Talk to us.

OpenBookChain

Don't trust the AI.
Check its sources.

Every answer traces to a record, a named approver and an on-chain timestamp.

Free · open source · no account · hello@openbookchain.com